Qualcomm Snapdragon Chipsets Camera Driver TOCTOU Race Condition Vulnerability

Vulnerability

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in the camera driver of various chipsets, including several Snapdragon mobile platforms. This vulnerability may lead to memory corruption while processing the optical image stabilization (OIS) packet parser. The issue arises from improper synchronization, allowing certain operations to be executed out of order, potentially causing memory to be accessed or modified incorrectly.

Impact

Exploitation of this vulnerability can cause memory corruption, which may lead to undefined behavior in the application, including potential arbitrary code execution or causing the device to crash.

Remediation

Qualcomm has released patches for this vulnerability. Instructions for applying the patch can be found in the Qualcomm June 2025 Security Bulletin.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.3
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.